DNSC draft: NIS2 training standard for management bodies and the list of 61 certifications
Romania’s National Cyber Security Directorate (DNSC) is preparing an act that changes how the management training obligation in GEO no. 155/2024 should be read: a draft decision approving the cybersecurity training standard for the management bodies of essential and important entities, together with the list of recognised cybersecurity certifications.
One clarification belongs in the first paragraph: the document analysed here is a draft, watermarked DRAFT on every page. It is not a legal act in force, it produces no legal effects yet, and it may change before publication in the Official Gazette. We analyse it because it shows, in unusual detail, what the authority will expect from directors and executives, and organisations that understand the logic early arrive prepared without emergency spending.
In short
- The draft defines a single training role: Executive Manager in Cybersecurity Governance, at strategic management level.
- The standard has 6 competence units, all about governance and oversight, not technical execution.
- Assessment is proposed as 50% crisis simulation and 50% governance portfolio, plus a multiple choice test.
- The curriculum is open: NIST CSF 2.0, ENISA ECSF, NIST SP 800-34 Rev. 1, ENISA Threat Landscape and national legislation.
- Annex 2 lists 61 recognised cybersecurity certifications.
- Status: draft, not an act in force.
Where the obligation comes from and why a standard appears now
Government Emergency Ordinance no. 155/2024, approved with amendments by Law no. 124/2025, provides in art. 14 that the management bodies of essential and important entities approve cybersecurity risk management measures, supervise their implementation and are liable for breaches of those obligations. The same article requires members of management bodies to follow periodic training enabling them to identify risks and assess risk management practices.
Until now the legal text had no minimum content attached to that training. In practice, “management training” has meant anything from a forty minute presentation to a serious governance programme. The draft decision fills exactly that gap: it states which competences must be demonstrated, at what level, and how they are verified.
The legal basis invoked in the draft is art. 5 letter b) and art. 7 paragraphs (3) and (4) of GEO no. 104/2021 establishing DNSC, approved by Law no. 11/2022, together with art. 14 paragraphs (2) and (4) of GEO no. 155/2024. In its draft form, the act is to be published in the Official Gazette, Part I.
The role the training targets
Annex no. 1 defines a single role, Executive Manager in Cybersecurity Governance, placed at strategic and executive management level. The wording matters, because it draws a clear line around what is and is not asked of a director or CEO.
The role assumes no technical execution skills. It assumes the ability to govern: to set the organisation’s risk appetite, approve policies, allocate resources, supervise and control. The most concrete element in the whole annex is the executive’s duty to formally designate the person responsible for the security of networks and information systems under art. 14 paragraphs (3) and (4) of GEO no. 155/2024, a role the document calls CISO.
The distinction the draft repeats in several places is between responsibility, meaning execution, which belongs to the designated officer, and accountability, which stays with executive management. The function can be delegated; the accountability cannot.
The six competence units
| Unit | What it actually requires |
|---|---|
| CU1. Assuming the legal liability framework | Identifying the entity’s legal status, essential or important; interpreting due diligence obligations, separating clearly what may be delegated from what may not under art. 14; integrating an all-hazards perspective. The document speaks of moving from assumed ignorance to informed diligence and refers to the sanctions regime. |
| CU2. Setting the context and strategy for cyber risk governance | Drafting a risk appetite statement, cost-benefit analysis of measures including ROSI, documented risk acceptance decisions and policy approval. Aligned to the GOVERN function of NIST CSF 2.0. |
| CU3. Organisation, delegation and resource allocation | Job description and KPIs for the designated officer, reporting lines that keep that officer independent from the IT function, the formal appointment decision, budgeting based on ROI and ROSI, supply chain security clauses and periodic audit of critical suppliers. |
| CU4. Compliance oversight and threat literacy | Executive understanding of relevant threats: ransomware with double extortion, CEO fraud and business email compromise, deepfakes. Out-of-band verification procedures, risk indicators that are more than technical statistics, phishing test results, audit trail. |
| CU5. Resilience and business continuity management | Separating business continuity, an executive responsibility, from disaster recovery, a technical one. Approving the plan with manual fallbacks, the crisis cell, the implications of paying a ransom, crisis communication, and incident reporting: early warning within 24 hours and a report within 72 hours under art. 15 of GEO no. 155/2024. Methodological reference: NIST SP 800-34 Rev. 1. |
| CU6. Auditability and documented compliance | Formalising risk acceptance, including decisions not to implement a measure for cost or operational reasons, periodic signing of the risk register, minutes of board meetings on security topics, archiving audit reports, evidence of training attendance, supervising registration in the entity register and the accuracy of information submitted to the authority. |
Read together, the six units describe a set of evidence rather than a set of knowledge. Almost every competence element translates into a signed document, a dated decision or a set of minutes. That is the most useful information for an organisation preparing now: management training will be verified through paperwork, not through diplomas.
How assessment is proposed
The assessment section is what sets this standard apart from a classic course. Two methods are proposed, weighted equally.
- Crisis simulation, wargaming style, 50%. The candidate receives a scenario such as ransomware triggered just before financial close and must decide under pressure: do we stop production, do we go public, do we switch to the manual procedure. Executive reasoning is assessed, not the technical fix.
- Governance portfolio and audit trail, 50%. Real or constructed documents are presented: the risk appetite statement, the RACI delegation matrix separating the board’s role from the designated officer’s, and the minutes of a risk review meeting.
- A multiple choice test is added to verify baseline knowledge.
The practical consequence is simple. A director who attended training but has no signed risk register, no appointment decision and no meeting minutes has nothing to submit for the portfolio half. Documentation is built over time, not in the week before assessment.
An open curriculum, with no dependence on commercial standards
The draft explicitly chooses an open curricular approach, based solely on public standards and national legislation, so that executive training is accessible nationwide. The indicated resources are:
- NIST Cybersecurity Framework 2.0, focused on the GOVERN function and the GV.OC, GV.RM, GV.RR, GV.PO, GV.SC and GV.OV categories;
- ENISA European Cybersecurity Skills Framework, the CISO profile;
- NIST SP 800-34 Rev. 1, for continuity planning;
- ENISA Threat Landscape, for the threat literacy component;
- applicable national legislation.
The document states that this choice does not exclude commercial, ISO or European standards, and that the same competences may also be acquired through certified individual training programmes. That is an important sentence for organisations that already run an information security management system and do not want to start over.
Annex 2: the list of 61 recognised certifications
The second annex contains the list of recognised cybersecurity certifications, grouped by issuing body. We reproduce it for orientation, noting again that it belongs to a draft and may change.
| Issuer | Certifications |
|---|---|
| (ISC)² | CISSP, CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP, SSCP, CAP, CC, S-ITSF, S-ITSP, S-ITSE, S-CITSO |
| CompTIA | CASP+, Security+ |
| ISACA | CISA, CISM, CRISC, CSX-F, CSX-T, CSX-P |
| GIAC | GSE, GCED, GSLC, GSNA, GISP, GSOC, GCIH, GDSA, GISF, GSEC |
| EC-Council | CEH, CEH Practical (Master), E|ISM, CCISO |
| EITCI | EITCA/IS |
| Mile2 | C)SP, C)ISSO, IS20, C)SLO, C)HISSP, C)ISMS-LA, C)ISMS-LI, C)ISSA, C)ISSM, C)ISRM, ISCAP |
| ASIS International | CPP, APP |
| CertNexus | CIoTSP, IRBIZ, CFR |
| GAQM | CISP, CISSM |
| HISPI | HISP |
| EC First | CCSA, CSCS, CMMP |
| IBITGQ | CCRMP, CIRM F, C CR P, CITGP, C CS F |
The list is relevant mainly for the person designated as responsible for the security of networks and information systems, not for every board member. A CEO does not need a CISSP in order to govern risk; they need the decisions and documents described in the competence units.
What the draft does not say
Three limits are worth keeping in mind, so that no false expectations are built.
- It is a draft. Numbering, deadlines and application details may change before publication in the Official Gazette.
- It does not turn any certification in Annex 2 into a compliance condition for the entity. Compliance is measured against the measures in GEO no. 155/2024 and the DNSC orders issued under it, not against diplomas.
- It does not replace the organisation’s own risk assessment. The standard describes what management must know, not which technical measures are sufficient in a given context.
What can be done now, whatever the final form
Every item required in the governance portfolio is a document an entity within the scope of GEO no. 155/2024 needs anyway. A reasonable order of work is the following.
- Confirm your classification. Essential or important, on what criterion, in which sector. Everything else follows from this.
- Issue the appointment decision for the officer responsible for the security of networks and information systems, with duties, reporting line and indicators.
- Approve the risk appetite statement and the security policy, dated and signed.
- Build the RACI matrix separating board accountability from execution responsibility.
- Write down the incident reporting procedure, with the 24 hour and 72 hour deadlines.
- Schedule a risk review meeting and keep the minutes. It is the cheapest portfolio item and the one most often missing.
For the first step, the CysNis platform walks through the classification criteria step by step and separates legal obligations from technical recommendations, so the board discussion starts from a clear status rather than an assumption.
For steps two to six, the documents do not have to be invented from scratch. The NIS2 documentation packages contain the editable templates for decisions, policies, registers and procedures that make up precisely the portfolio described in the draft standard. If the organisation prefers to establish the real distance to the requirements first, the starting point is a NIS2 compliance assessment with a remediation plan, carried out on evidence rather than declarations. ProDefence is a NIS auditor accredited by DNSC.
Where the organisation has no internal person to carry the process and face the authority, the role can be covered through an outsourced NIS2 officer, accountable for deadlines, documentation and the relationship with DNSC. The duty to appoint this officer falls on essential and important entities alike, a point analysed at length in the article on the NIS2 officer at important entities. Which of the three approaches fits best, in-house, consultant or outsourced role, is discussed at length in the article on implementing NIS2 requirements in Romania, three routes.
Frequently asked questions
Is the draft decision binding now?
No. The document is watermarked DRAFT and is not a legal act in force. The obligation to train management bodies already exists, however, under art. 14 of GEO no. 155/2024, approved by Law no. 124/2025.
Must the CEO obtain one of the 61 certifications?
The draft provides nothing of the sort. The Annex 2 list concerns professional cybersecurity competences, relevant mainly for the designated officer. For management, the standard describes governance competences, evidenced through decisions and documents.
What does assessment by simulation mean?
Half of the proposed assessment is a crisis exercise in which decisions are taken under pressure, for example in a ransomware scenario. Executive reasoning is what is examined, not the technical solution.
What is the difference between accountability and responsibility here?
Execution responsibility belongs to the officer responsible for the security of networks and information systems, designated by management. Accountability stays with the management body and cannot be delegated.
Which documents make up the governance portfolio?
The risk appetite statement, the RACI delegation matrix between the board and the designated officer, and the minutes of a risk review meeting. The rest of the standard adds the signed risk register, the appointment decision and evidence of training.
Which incident reporting deadlines are mentioned?
An early warning within 24 hours and an incident report within 72 hours, under art. 15 of GEO no. 155/2024.
The document analysed is a draft decision of the National Cyber Security Directorate approving the cybersecurity training standard for the management bodies of essential and important entities and the list of cybersecurity certifications. It is watermarked DRAFT on every page and is not a legal act in force. The analysis above is informative and does not constitute legal advice.


